EconPapers    
Economics at your fingertips  
 

Android Permission System Violation: Case Study and Refinement

Kyoung Soo Han, Yeoreum Lee, Biao Jiang and Eul Gyu Im
Additional contact information
Kyoung Soo Han: Department of Computer and Software, Hanyang University, Seoul, South Korea
Yeoreum Lee: Department of Computer and Software, Hanyang University, Seoul, South Korea
Biao Jiang: Microsoft (China), Co., Ltd., Shanghai, China
Eul Gyu Im: Division of Computer Science and Engineering, Hanyang University, Seoul, South Korea

International Journal of E-Entrepreneurship and Innovation (IJEEI), 2013, vol. 4, issue 1, 16-27

Abstract: Android uses permissions for application security management. Android also allows inter-application communication (IAC), which enables cooperation between different applications to perform complex tasks by using some components and Intents. In other words, Android provides more flexibility and places less restriction on application development. This is a major feature that differentiates Android from its competitors. However, IAC also facilitates malicious applications that can collude in attacks of privilege escalation. In this paper, the authors demonstrate with case studies that all IAC channels can potentially be utilized for privilege escalation attacks, and the authors propose a refinement to solve this problem by enforcing IAC permissions and exposing IAC to users.

Date: 2013
References: Add references at CitEc
Citations:

Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 4018/jeei.2013010102 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:igg:jeei00:v:4:y:2013:i:1:p:16-27

Access Statistics for this article

International Journal of E-Entrepreneurship and Innovation (IJEEI) is currently edited by Charice Hayes

More articles in International Journal of E-Entrepreneurship and Innovation (IJEEI) from IGI Global
Bibliographic data for series maintained by Journal Editor ().

 
Page updated 2025-03-19
Handle: RePEc:igg:jeei00:v:4:y:2013:i:1:p:16-27